The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.
2018-09-07T05:29:00.357
2024-11-21T03:53:08.627
Modified
[email protected]
CVSSv3.0: 7.2 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0